Cybercriminals are orchestrating sophisticated, multinational fake online shop operations across Europe, impersonating major brands like Samsung, Nike, and Amazon. These scams leverage social media, WhatsApp, and email to trick consumers into purchasing counterfeit goods, sharing personal information, or falling victim to World Cup-themed promotions. The operations are highly organized, utilizing rotating domains, misleading redirects, and localized content to evade detection and maximize reach.

A recent investigation by Bitdefender Labs has uncovered a significant escalation in fake online shop campaigns targeting consumers across 12 European countries between March and May 2026. These operations, far from being isolated incidents, are now functioning as coordinated, multinational businesses employing professional e-commerce tactics.
Attackers are impersonating globally recognized brands such as Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. They employ a multi-channel approach, utilizing Facebook ads, WhatsApp messages, email, SMS, phone calls, and fraudulent websites to lure victims. The ultimate goals range from direct financial theft through fake payments to acquiring sensitive personal information or selling counterfeit merchandise.
Researchers mapped over 40 domains linked to these fraudulent activities, noting a pattern of reused infrastructure and tactics across different countries and brands. Methods to evade detection include rotating domain names, employing misleading redirects, and leveraging Unicode lookalike domains that visually mimic legitimate URLs. Some operators have even established counterfeit supply chains through platforms like WhatsApp, using password-protected catalogs to showcase their illicit goods.
Several campaigns have capitalized on the anticipation surrounding the 2026 FIFA World Cup, promising exclusive merchandise or special deals to exploit consumer excitement. For instance, one campaign offered Samsung Galaxy S26 Ultra devices at a 90% discount, while another promoted free Adidas Deutschland 2026 Fan Kits.
The scale and sophistication of these operations are notable. Campaigns are localized to specific European markets, with tailored messaging and content. For example, a ZARA and Nike impersonation campaign originating from a Polish hub used the same domain and advertising identity, indicating a shared operational backend.
WhatsApp has emerged as a significant platform for counterfeit goods distribution. One operator, identified as "Carl," contacted European users via WhatsApp, offering "1:1 quality" counterfeit products and directing them to password-protected Yupoo catalogs. This network appears to be China-based, with DHL shipping offered to Europe.
Beyond direct sales scams, some operations focus on subscription traps or data harvesting. Amazon clone sites were identified, designed to exploit the brand's trust to collect payment details or enroll unsuspecting users into unwanted subscriptions.
The investigation highlights the evolution of these fake-shop networks, which now operate with significant advertising budgets and infrastructure designed to bypass traditional security measures. The reuse of domain infrastructure and the adaptation of tactics across various brands underscore the organized nature of these cybercriminal enterprises.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed